Skip to content

What is curral?

curral is a secure SQL gateway for DuckDB. It puts your DuckDB databases and Iceberg lakes behind an HTTP API, and decides for every statement who may run it, which rows they see and which columns arrive masked.

Curral is Portuguese for “corral”: the place where you keep the herd in and decide who gets through the gate.

DuckDB is a great engine, but it has no users, no permissions and no network protocol. Sharing a DuckDB file or an Iceberg lake usually means one of two things:

  • handing out raw storage credentials, so everyone can read everything;
  • building and maintaining a custom API for each use case.

curral is the missing layer between the two: one binary that speaks HTTP on one side and DuckDB on the other.

One binary DuckDB is embedded. Databases and catalogs declared in a config file are attached at startup.
Policy as code Access rules are written in Rego and evaluated by an embedded OPA.
Real inspection The policy sees the base tables a statement really reads (views, CTEs and joins included), taken from DuckDB’s own planner, not a regex.
Row-level security and masking Queries are rewritten before they run, so filters and joins cannot be used to guess hidden values.
Your lake Anything DuckDB can ATTACH: DuckDB files, Iceberg REST catalogs (including Cloudflare R2 Data Catalog), Postgres, S3.
Production features TLS, brute-force lockout, per-role limits, a fail-closed audit log, Prometheus metrics, hot reload with SIGHUP.
Friendly to tools and agents /v1/schema lists only what the caller may query, dry_run explains a decision without executing, Arrow streams into pandas, polars or DuckDB.